Triple-A Security Incident: Post-Mortem

On 25 July 2026, Triple-A identified unauthorized access to certain operational wallets containing the company’s own digital assets. The incident was contained within approximately three hours. Every client transaction and settlement continued as normal across every market.
Security breaches are nothing new to the fintech and payments industries. As is often the case, this attack did not come through a flaw in a smart contract or a failure of infrastructure, but rather through social engineering.
Yet, the design of how Triple-A operates, holds, and manages assets ensured that the attacker was unable to reach client funds. The loss was limited to treasury assets that Triple-A uses for our own conversions and it has been fully absorbed by our reserves.
Below, we walk through exactly what happened, how the attack unfolded, why client funds sat entirely outside the blast radius, and the security measures we've launched in response.
Timeline of events
25 July 2026, approximately 2:39 AM GMT:
Triple-A identified unauthorized access to certain wallets operated by its Singapore entity and containing the company’s own digital assets.
25 July 2026, immediately after the attack:
Triple-A activated its incident response procedures, formed an incident committee and engaged external cybersecurity and blockchain forensics specialists. Certain services were placed in maintenance mode while security checks were completed. MAS and the Singapore Police Force were notified.
25 July 2026, approximately 5:15 AM
Following containment and initial verification, services were restored. Transactions and settlements resumed normally across all markets.
25–27 July 2026
Triple-A confirmed that client funds, transactions, and settlements were unaffected. Merchants and key partners were informed directly, followed by public updates and merchant communications on 27 July.
From 25 July 2026 to date
Sygnia and zeroShadow, two reputed cybersecurity expert firms, have been engaged to support the forensic investigation, asset tracing, and recovery. Additional safeguards, access controls, and monitoring are being implemented in parallel.
How the attack happened
The attackers used advanced social engineering techniques to compromise credentials associated with a member of Triple-A’s engineering team.
Social engineering is often perceived as an oddly-formatted email with a phishing link. However, in this case, it was a multi-step attack that included communications across different channels, impersonation, and a live call.
The attacker then gained unauthorized access to an operational environment and obtained higher-level system permissions. Following the initial compromise, the attacker deployed additional malware, accessed production databases, abused legitimate API credentials, and executed unauthorized cryptocurrency withdrawals.
The attack was targeted and meticulously prepared. This once again highlights the importance of continuous employee training and threat awareness, since employees are the last line of defense for any company.
Why client funds were not at risk
Client funds were not in the path of this attack because of how Triple-A is built. For the attacker, a route to access these funds simply did not exist.
The wallets involved in this incident were operational wallets belonging to Triple-A Technologies Pte. Ltd., our Singapore entity. They hold only Triple-A's own digital assets. Triple-A Singapore does not provide custodial services for digital assets.
Customer funds are deliberately kept in an entirely different structure. They are held in segregated trust accounts with established safeguarding institutions, including DBS and Standard Chartered, at regulated banks. They are kept separate from the company’s own funds and are not reachable from the operational environment the attacker compromised.
No other Triple-A regulated entities or regional operations were affected. Services were restored across all markets and have operated normally since. Triple-A remains well capitalized and continues to meet all of its liabilities in full.
Despite this, we do not treat this incident lightly. The response and remediation have been managed with the seriousness they deserve.
Our response and security improvements
When the unauthorized access was identified, Triple-A activated established incident response procedures, convened a dedicated incident committee, and placed affected services into maintenance mode while the environment was verified.
MAS and the Singapore Police Force were notified immediately. Forensic and blockchain-tracing specialists were engaged within hours. Sygnia led the forensic investigation and strengthened security controls, and zeroShadow was engaged to trace the affected assets and support recovery efforts.
Following the containment of the incident, a broader security improvement program was implemented and is being rolled out in phases under the guidance of external cybersecurity professionals.
These are the steps we are taking to reduce the possibility of another attack:
- Reducing access to production systems, tightening approval and authentication requirements for sensitive wallet activity, and rotating and restricting credentials and access tokens
- Increasing the separation between our corporate, production, and operational wallet environments so that access to one does not open a path to the others
- Expanding logging, anomaly detection, real-time monitoring, and alert systems, with additional controls to flag credential misuse or attempted re-entry
- Reviewing wallet exposure limits and the controls governing how and when assets can move
- Strengthening emergency containment and recovery procedures, and commissioning independent security testing and validation
Threat landscape: Lessons for the industry
The attack on Triple-A was patient, multi-channel, and convincing enough to exploit trust through social engineering.
The threat came as a coordinated effort to impersonate, build credibility, and manipulate a single moment of human judgment. This is part of the system that is hardest to patch: the people who operate it.
For the industry, we believe that any organization, however well defended, must operate on the assumption that a determined attacker will eventually breach those defenses. What separates a contained incident from a catastrophic one is what the attacker is able to reach once they do manage to get in.
Triple-A intends to openly share what we learn from this incident with other companies where doing so will help others strengthen their own defenses. The security of any one participant contributes to trust in the system as a whole.
Ongoing investigation and what’s next
The investigation is ongoing. It is being conducted together with Sygnia, zeroShadow, and the Singapore Police Force, and in continued coordination with MAS.
It has already established a detailed understanding of the incident, including how the initial compromise occurred, the sequence of the attacker's activity, the scope of what was accessed, and the steps needed to secure the environment.
Immediate containment is complete: active attacker access has been removed and the persistence mechanisms identified during the investigation have been eliminated.
The focus has now shifted to tracing the movement of the affected assets and to potential freezing and recovery actions. Tracing and recovering stolen digital assets is difficult and often slow, and we will not overstate the likelihood of return. However, the effort is active and ongoing.
From a business and product standpoint, Triple-A continues to meet all of its liabilities in full and is operating at normal service levels across all markets.


